Ransom

Ransom:Win32/Magniber information

Malware Removal

The Ransom:Win32/Magniber is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Magniber virus can do?

  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Ransom:Win32/Magniber?


File Info:

name: 19599CAD1BBCA18AC647.mlw
path: /opt/CAPEv2/storage/binaries/fb6c80ae783c1881487f2376f5cace7532c5eadfc170b39e06e17492652581c2
crc32: E8BD91E9
md5: 19599cad1bbca18ac6473e64710443b7
sha1: f9e2111e2903838bb9f4efb557f75745d028bc3e
sha256: fb6c80ae783c1881487f2376f5cace7532c5eadfc170b39e06e17492652581c2
sha512: e30bfdb9c8c836f1972759f0fc6827dc08dc1c76d096097ab1ae9613e88d3c5239e9c6adaa84deff12a49bb04d680538c22d01acab40655385a9478d97c2c354
ssdeep: 768:AFRmQk/E36GvOoIRNiKRGqwOgv4+punwRbYhM:AFwj/W6GsRN4vb0w9
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T126F28405EF9EC3DECE4A18B0207BBF67A5792C07013DA2A7EFA01D756018F51B16B954
sha3_384: f72d7cf13ef8dff5ddb965f8acd610582c4a9f657919bb91b00e802b454fe18f79f0673cb2074d54df2c076f6354a0d9
ep_bytes: 558bec568b750c5783fe017517e86e00
timestamp: 2018-07-05 17:38:05

Version Info:

0: [No Data]

Ransom:Win32/Magniber also known as:

BkavW32.Common.2B14A1A6
LionicTrojan.Win32.Magniber.j!c
DrWebTrojan.Encoder.26351
MicroWorld-eScanTrojan.Agent.DBRD
FireEyeGeneric.mg.19599cad1bbca18a
CAT-QuickHealRansom.Magniber.S3759400
SkyhighGenericRXGH-CC!19599CAD1BBC
ALYacTrojan.Ransom.Magniber
Cylanceunsafe
ZillyaTrojan.GenericKD.Win32.138194
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Magni.6584dcc8
K7GWTrojan ( 00537d441 )
K7AntiVirusTrojan ( 00537d441 )
BitDefenderThetaGen:NN.ZedlaF.36744.cq4@a0EaIGm
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Filecoder.Magniber.C
APEXMalicious
KasperskyTrojan-Ransom.Win32.Magni.bdl
BitDefenderTrojan.Agent.DBRD
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:Metasploit-F [Expl]
TencentWin32.Trojan.Filecoder.Yfow
SophosTroj/Magni-A
F-SecureTrojan.TR/Magniber.wnyqk
VIPRETrojan.Agent.DBRD
TrendMicroRansom_MAGNIBER.R
EmsisoftTrojan.Agent.DBRD (B)
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan-Ransom.Magniber.A
JiangminTrojan.Magni.j
WebrootW32.Trojan.GenKD
VaristW32/Trojan.EBQK-4076
AviraTR/Magniber.wnyqk
Antiy-AVLTrojan[Ransom]/Win32.Magniber
KingsoftWin32.Troj.General.lc
XcitiumMalware@#3hc0hqbid4zp5
ArcabitTrojan.Agent.DBRD
ViRobotTrojan.Win32.S.Agent.35328.VY
ZoneAlarmTrojan-Ransom.Win32.Magni.bdl
MicrosoftRansom:Win32/Magniber
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Magniber.R231851
McAfeeGenericRXGH-CC!19599CAD1BBC
MAXmalware (ai score=100)
VBA32TrojanRansom.Magni
PandaTrj/CI.A
TrendMicro-HouseCallRansom_MAGNIBER.R
RisingTrojan.Generic@AI.83 (RDML:wCSuG6VbbQ36jum3UUQ0ow)
YandexTrojan.GenAsa!O1gFzl69+n0
IkarusTrojan-Ransom.Magniber
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.AP.14ABB62!tr
AVGWin32:Metasploit-F [Expl]
DeepInstinctMALICIOUS

How to remove Ransom:Win32/Magniber?

Ransom:Win32/Magniber removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment